openvpn 2.5.1-1ubuntu1.1 source package in Ubuntu

Changelog

openvpn (2.5.1-1ubuntu1.1) hirsute-security; urgency=medium

  * SECURITY UPDATE: Authentication bypass with deferred authentication
    - debian/patches/CVE-2020-15078-pre1.patch: move context_auth from
      context_2 to tls_multi and name it multi_state in
      src/openvpn/forward.c, src/openvpn/multi.c, src/openvpn/openvpn.h,
      src/openvpn/push.c, src/openvpn/ssl_common.h.
    - debian/patches/CVE-2020-15078-pre2.patch: fix condition to generate
      session keys in src/openvpn/ssl.c.
    - debian/patches/CVE-2020-15078-1.patch: move auth_token_state from
      multi to key_state in src/openvpn/auth_token.c,
      src/openvpn/ssl_common.h, src/openvpn/ssl_verify.c,
      tests/unit_tests/openvpn/test_auth_token.c.
    - debian/patches/CVE-2020-15078-2.patch: ensure auth-token is only sent
      on a fully authenticated session in src/openvpn/ssl_verify.c.
    - debian/patches/CVE-2020-15078-3.patch: ensure key state is
      authenticated before sending push reply in src/openvpn/push.c.
    - CVE-2020-15078

 -- Marc Deslauriers <email address hidden>  Tue, 27 Apr 2021 10:03:40 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Hirsute
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openvpn_2.5.1.orig.tar.xz 1.1 MiB 40930489c837c05f6153f38e1ebaec244431ef1a034e4846ff732d71d59ff194
openvpn_2.5.1-1ubuntu1.1.debian.tar.xz 69.2 KiB 0a6f25189ed394784e1aadbab5c58a40d1c33a8455ced268023ce2394941f153
openvpn_2.5.1-1ubuntu1.1.dsc 2.2 KiB dd54beed0ad17a8c49e6d8dd67bc75212c87c78e2008f61abecf5ec6cca00257

View changes file

Binary packages built by this source

openvpn: No summary available for openvpn in ubuntu hirsute.

No description available for openvpn in ubuntu hirsute.

openvpn-dbgsym: No summary available for openvpn-dbgsym in ubuntu hirsute.

No description available for openvpn-dbgsym in ubuntu hirsute.